Privacy Policy
This Privacy Policy explains how ShrimpHut collects, uses, stores, and protects personal data when you browse the website, place an order, create an account, subscribe to marketing, or contact us. We aim to handle personal data in line with applicable UK data protection law, including the UK GDPR and the Data Protection Act 2018.
Who this policy applies to
This policy applies to customers, account holders, newsletter subscribers, and anyone who uses the ShrimpHut website or contacts us about products, orders, livestock, support, or aftercare.
What personal data we may collect
- Identity and contact details such as your name, email address, telephone number, billing address, and delivery address.
- Order and account information such as account activity, order history, invoices, transaction references, delivery selections, and customer-service messages.
- Technical and usage data such as IP address, browser details, session identifiers, login attempts, and website interactions needed to keep the site secure and functioning properly.
- Marketing and preference data such as newsletter subscription status, consent records, cookie choices, and communication preferences.
How we collect information
We collect information directly from you when you place an order, register an account, subscribe to the newsletter, submit a contact form, or communicate with support. We also collect limited technical data automatically through cookies, sessions, and security logging when you use the website.
How we use personal data
- To process orders, take payment, arrange dispatch, provide order updates, and handle delivery queries.
- To provide customer support, respond to contact requests, and review DOA or damage claims.
- To maintain account features such as saved addresses, order history, login security, and account recovery.
- To prevent fraud, protect the website, monitor abuse, and maintain system security.
- To comply with legal, accounting, tax, and record-keeping obligations.
- To send marketing emails where you have subscribed or where another lawful basis applies.
Lawful bases we rely on
Depending on the situation, we rely on one or more of the following lawful bases: performance of a contract, compliance with a legal obligation, legitimate interests, and consent. For example, we use contract as the basis for processing order and delivery information, legal obligation for retaining tax and accounting records, legitimate interests for security and fraud prevention, and consent for optional marketing where required.
Who we may share data with
We may share relevant information with service providers and partners where necessary to run the store, such as payment processors, delivery companies, email delivery providers, website hosting providers, and fraud or security tools. We only share the information reasonably needed for the relevant purpose.
How long we keep information
We retain information only for as long as reasonably necessary for the purposes described above, including legal, tax, accounting, dispute-resolution, fraud-prevention, and operational reasons. Order, invoice, and related transaction records may need to be kept for several years even if an account is later closed.
Your rights
Depending on the circumstances, you may have the right to request access to your personal data, request correction of inaccurate information, request deletion, object to certain processing, request restriction, request portability, or withdraw consent where processing depends on consent. These rights are not absolute and may be limited where we have overriding legal or operational obligations.
Marketing
You can unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting [email protected]. Transactional messages relating to orders, accounts, security, invoices, or support are not marketing and may still be sent where necessary.
Cookies and website tracking
Our use of cookies is explained in the Cookie Policy. Where optional analytics or marketing cookies are used, they should only be enabled through the relevant consent tools.
Security
We use reasonable technical and organisational measures to protect personal data, including account controls, session protections, access restrictions, and other security safeguards. No website or transmission method is completely risk free, so customers should also protect their own login details and device security.
Contact and complaints
If you have a privacy question or wish to exercise your rights, contact [email protected]. If you remain unhappy after contacting us, you may also have the right to complain to the Information Commissioner's Office in the UK.